Risk assessment
Abstract
A method is provided in accordance with an aspect of the present disclosure. The method includes processing data related to a plurality of security risk metrics for an entity and identifying a change in at least one of the security risk metrics. The security risk metrics are associated with risk component data. The method also includes defining determining modifications in risk assessment data that is associated with the risk component data based on the change in the at least one of the security risk metrics, and displaying information about the risk assessment data and the risk component data.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
processing data related to a plurality of security risk metrics for an entity; identifying a change in at least one of the security risk metrics, wherein the security risk metrics are associated with risk component data; determining modifications in risk assessment data that is associated with the risk component data based on the change in the at least one of the security risk metrics; and displaying information about the risk assessment data and the risk component data.
2 . The method of claim 1 , wherein the risk assessment data includes business objectives data, business processes data, and information assets data, and wherein the risk component data includes security threats data, security vulnerabilities data, and security incidents data.
3 . The method of claim 2 , further comprising:
identifying a plurality of business objectives from the business objectives data; comparing the plurality of business objectives; and prioritizing the plurality of business objectives.
4 . The method of claim 3 , further comprising:
identifying a plurality of business processes supporting the business objectives from the business processes data; assessing each of the plurality of business processes in relation to the business objectives; and linking the plurality of business processes to the business objectives.
5 . The method of claim 4 , further comprising:
identifying a plurality of information assets supporting the business processes from the information assets data; assessing each of the plurality of information assets in relation to the business processes; and linking the plurality of information assets to the business processes.
6 . The method of claim 5 , further comprising:
identifying a plurality of incidents from the security incidents data; assessing each of the plurality of incidents in relation to the information assets; and linking the plurality of incidents to the information assets.
7 . The method of claim 6 , further comprising:
identifying a plurality of security vulnerabilities from the security vulnerabilities data; assessing each of the plurality of security vulnerabilities in relation to the incidents; and linking the plurality of security vulnerabilities to the incidents.
8 . The method of claim 7 , further comprising:
identifying a plurality of security threats from the security threats data; assessing each of the plurality of security threats in relation to the security vulnerabilities; and linking the plurality of security threats to the security vulnerabilities.
9 . A system comprising:
a computing device having at least one processing device with a control unit to
analyze data related to a plurality of security risk metrics for an entity, wherein the plurality of security risk metrics are associated with security threats linked with security vulnerabilities that are further linked with security incidents;
link the security incidents with information assets linked with business processes that are further linked with business objectives;
determine when at least one of the security risk metrics exceeds a threshold;
generate graphical incident alert information when the at least one of the security risk metrics is associated with at least one security incident, wherein the incident alert information is associated with at least one business objective; and
generate risk trend information when the at least one of the security risk metrics is associated with at least one security threat or at least one the security vulnerability, wherein the risk trend information is associated with at least one business objective.
10 . The system of claim 9 , wherein the control unit is further to:
receive an input to compare the business objectives; prioritize the business objectives; receive an input to assess each of the business processes supporting the business objectives in relation to the business objectives; and receive an input to assess each of the information assets supporting the business processes in relation to the business processes.
11 . The system of claim 10 , wherein the control unit is further to:
receive an input to assess each of the incidents in relation to the information assets; receive an input to assess each of the security vulnerabilities in relation to the incidents; and receive an input to assess each of the security threats in relation to the security vulnerabilities.
12 . A non-transitory machine-readable storage medium encoded with instructions executable by at least one processing, the machine-readable storage medium comprising instructions to:
collect data related to a plurality of security risk metrics for an entity, wherein the data related to the plurality of security risk metrics is associated with risk component data; associate the risk component data with risk assessment data for the entity; analyze the data related to the plurality of security risk metrics to determine when at least one of the security risk metrics exceeds a threshold; and provide information about corresponding changes in the risk assessment data based on the change in the at least one of the security risk metrics.
13 . The non-transitory machine-readable storage medium of claim 12 , wherein the risk assessment data includes a plurality of business objectives, a plurality of business processes, and a plurality of information assets, and wherein the risk component data includes a plurality of security threats, a plurality of security vulnerabilities, and a plurality of security incidents.
14 . The non-transitory machine-readable storage medium of claim 13 , further comprising instructions to:
compare the plurality of business objectives; prioritize the plurality of business objectives; assess each of the plurality of business processes supporting the plurality of business objectives in relation to the business objectives; link the plurality of business processes to the business objectives; assess each of the plurality of information assets supporting the plurality of business processes in relation to the business processes; and link the plurality of information assets to the business processes.
15 . The non-transitory machine-readable storage medium of claim 14 , further comprising instructions to:
assess each of the plurality of incidents in relation to the plurality of information assets; link the plurality of incidents to the information assets; assess each of the plurality of security vulnerabilities in relation to the plurality of incidents; link the plurality of vulnerabilities to the incidents; assess each of the plurality of security threats in relation to the plurality of security vulnerabilities; and link the plurality of security threats to the security vulnerabilities.Join the waitlist — get patent alerts
Track US2017054750A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.